Usable with caveats: this is a clearly documented, licensed module from an organization-backed repository, but it has only one release and all recent commits come from one contributor. The repository also lacks a security policy and automated security scanning.
70%
Total Score
67
100
88
88
The package is only 40 days old and has one release, so there is not enough release history to establish long-term maintenance or stability.
All recent commits come from one contributor, creating a meaningful continuity risk. Organization backing provides some ability to hand off maintenance, but no second active contributor is shown.
There was one commit in the last three months from one active maintainer. That demonstrates recent activity but provides only weak evidence of sustained maintenance for a new package.
Composer is used as a build tool, but no automated security scanning tools are reported, leaving a security-maintenance gap.
The repository has no published security policy, reducing transparency about how vulnerabilities would be reported and handled.
We didn't find any vulnerabilities for this package.
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
magento/framework Version >=2.4.8 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.